logo

Critical Red Hat Keycloak Password Reset Flaw Enables Unauthenticated Account Takeover

ID: 05ad981a-a7c1-5f1f-b704-4ce869983365

STIX ID: report--05ad981a-a7c1-5f1f-b704-4ce869983365

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

Author: Divya

...
...

Red Hat disclosed CVE-2026-18963, a critical (CVSS 3.1 9.1) vulnerability in the Red Hat Build of Keycloak's reset-credentials flow that lets unauthenticated remote attackers bypass password-reset email verification and set new passwords to seize user accounts; Red Hat issued fixes on August 18, 2026 for affected builds and advises applying updates immediately or disabling the "Forgot password" feature as a temporary mitigation while reviewing logs and invalidating suspicious sessions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.